Skip to content

Endpoints & authentication

Region Endpoint
Europe eu.tpp.io:8888
Americas us.tpp.io:8888
Asia Pacific asia.tpp.io:8888

Connect to the region closest to your infrastructure. The gateway only decides where your connection enters the network; the exit IP is chosen by your targeting, and the full pool is reachable from every region.

Every gateway speaks three protocols on TCP port 8888, auto-detected (port 1080 serves exactly the same):

  • HTTP CONNECT - what curl -x http://... and most HTTP clients use. HTTPS traffic tunnels through this.
  • Plain HTTP forwarding - absolute-form requests (GET http://host/path) for plain-HTTP targets.
  • SOCKS5 - with username/password authentication. Works for any TCP protocol.

The same gateways accept HTTP/3 CONNECT on UDP port 1080 only, over QUIC with TLS. One QUIC connection carries many concurrent tunnels with no head-of-line blocking between them, and a resumed connection costs no extra round trip - worth it if you open many short-lived connections, or from a lossy or high-latency network.

Send a CONNECT request whose :authority is your target host:port, with your credential in a Proxy-Authorization: Basic header. Authentication and targeting are identical to the TCP protocols, and every option in targeting works the same way.

Client support is the catch. HTTP/3 to a proxy is much less widely implemented than HTTP/3 to a website, and curl does not support it at all - --http3 applies to the origin connection, and there is no proxy equivalent. Today this needs a client built directly on an HTTP/3 library, such as h3 with quinn in Rust, or aioquic in Python. If your client cannot do it, use the TCP port - there is no loss of function, only of the multiplexing.

Two other limits are worth knowing. Only CONNECT is accepted over HTTP/3 - plain HTTP forwarding needs the TCP port. And QUIC ends at the gateway: the exit leg is always TCP, so this does not proxy UDP traffic to your target.

Target hosts can be domains, IPv4 or IPv6 addresses. Domains are resolved from the exit’s network vantage, so geo-fenced content resolves the way it would for that household - prefer socks5h:// over socks5:// in clients that distinguish them, so your machine doesn’t resolve the name locally.

Credentials go in the proxy username and password:

Terminal window
curl -x http://USER:PASS@eu.tpp.io:8888 https://example.com

The username is your proxy user, optionally followed by targeting options (USER-cc-de-session-abc). The password is always just your proxy password.

Proxy usernames are 3-64 characters of letters, digits, _ or . - no hyphens, since the hyphen separates targeting options. Credential changes made in the dashboard or API reach the gateways within a few seconds.

A failed authentication (HTTP 407, or a SOCKS5 auth failure) means one of:

  • wrong username or password
  • a malformed or unknown targeting option - options are validated, never silently ignored
  • your bandwidth balance is exhausted
  • your account is disabled

Usage is metered in bytes, both directions, against your prepaid balance. When the balance runs out, authentication starts failing - connections are never cut mid-transfer. Check your balance on the dashboard or via GET /v1/me.